The Kremlin-backed Sandworm hacking group has adopted a new social engineering technique that uses fake CAPTCHA verification prompts to trick users into running malicious code, according to a warning from Ukraine's computer emergency response team (CERT-UA). The campaign targets users visiting compromised websites, where they encounter what appears to be a standard CAPTCHA security check.
Sandworm, also tracked as APT44 and Voodoo Bear, is a Russian military intelligence unit known for destructive cyberattacks against Ukraine's critical infrastructure. The group has previously deployed NotPetya ransomware and targeted Ukrainian power grids. This latest campaign represents a shift toward exploiting user trust in routine security mechanisms rather than relying solely on technical vulnerabilities.
The attack works by presenting victims with fake CAPTCHA pages on compromised websites. Instead of clicking images or typing text, users are instructed to perform actions that execute malicious code on their systems. The technique takes advantage of users' familiarity with CAPTCHA checks, which have become ubiquitous across the internet as a standard security measure. By mimicking this trusted interface, attackers lower victims' natural suspicion.
The campaign primarily affects users in Ukraine, though the technique could be adapted for broader targeting. Organizations with web-facing assets face increased risk if their sites are compromised and used as distribution points. Individual users who frequently interact with Ukrainian websites or services are most vulnerable to this specific operation.
Security teams should monitor for unusual CAPTCHA implementations on their web properties and educate users about this threat. Users should verify they are on legitimate websites before following any CAPTCHA instructions, especially those requesting unusual actions beyond standard image selection or text entry. Organizations should implement web application firewalls and conduct regular security audits of public-facing sites. Any CAPTCHA that asks users to run commands, download files, or perform actions outside the browser should be treated as suspicious and reported to security teams.
Source: https://www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself


